Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Emotet #Feodo #Banking #Trojan #Malware
- ----------------------------------------------
- 15-06-2018 IOC's
- ----------------------------------------------
- Main object- "ups-invoice-uscan-066M6846_7.doc"
- sha256 c945b58818a11af53b96cebb450f4558251d5164503608eec161e86f2e21a8d7
- sha1 122bfceb3603a58c95925499aca640513581b053
- md5 08f50f502b66b496fda8cb6b0b69386a
- Dropped executable file
- sha256 C:\Users\admin\AppData\Local\Temp\416674.exe b1bf9557f76b74ecc63989d0d43b13bf2980973b1455af0923e852577e382913
- DNS requests
- domain www.ikuznetsoff.ru
- Connections
- ip 52.109.88.5
- ip 2.16.186.97
- ip 52.109.88.10
- ip 13.107.5.88
- ip 52.109.112.33
- ip 52.109.76.36
- ip 108.51.20.17
- ip 31.31.196.195
- ip 2.18.232.50
- ip 2.16.4.178
- ip 2.16.186.74
- ip 2.18.233.62
- HTTP/HTTPS requests
- url http://108.51.20.17/
- url hxxp://www.ikuznetsoff.ru/MQ1qJe5Mjc/
- hxxp://www.anton.pskovhelp.ru/bALVX4cW/
- hxxp://www.redridgeumc.org/ hxxp://www.bilginerotoekspertiz.com/ZOfBFx7/
- hxxp://www.admin.searchlowestprice.com/G8W0S5EWs/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement